← Back to CVE List

CVE-2020-6323

Published: 2020-10-15T02:15Z
Last Modified: 2024-11-21T05:35Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SAP NetWeaver Enterprise Portal (Fiori Framework Page) versions - 7.50, 7.31, 7.40, does not sufficiently encode user-controlled inputs and allows an attacker on a valid session to create an XSS that will be both reflected immediately and also be persisted and returned in further access to the system, resulting in Cross Site Scripting. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt